Open
Description
1.12.0 does not have this issue
our workflow goes:
- login to ghcr.io
- login to docker hub where we have scout access
- build image
- push image to ghcr.io
- scan image
this is the error we see on 1.13.0 we are not seeing on 1.12.0
cves
...Storing image for indexing
✓ Image stored for indexing
...Indexing
✓ Indexed 412 packages
✓ Provenance obtained from attestation
Error: could not list CVEs for the image: API operation failed: Message: Not allowed, Locations: [], Extensions: map[arguments:map[context:$context query:map[imageCoords:map[digest:$digest hostname:$hostname repository:$repository] includeExcepted:$includeExcepted packageUrls:$purls]] code:DOWNSTREAM_SERVICE_ERROR status:FORBIDDEN], Path: [vulnerabilitiesByPackageForImageCoords]
![Screenshot 2024-08-06 at 11 57 44 PM](https://private-user-images.githubusercontent.com/1445228/355669842-954f56cf-a7b9-49c7-8404-653da6d1451c.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzg5Mjg0NzIsIm5iZiI6MTczODkyODE3MiwicGF0aCI6Ii8xNDQ1MjI4LzM1NTY2OTg0Mi05NTRmNTZjZi1hN2I5LTQ5YzctODQwNC02NTNkYTZkMTQ1MWMucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI1MDIwNyUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNTAyMDdUMTEzNjEyWiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9ZTc3ZmUxNmE4MjgxN2EwYzViMGQwZmU1OGE0N2I1YzZmNGIxMDYzZDQwMWExYTBjNThiYTY2MTAzOWY4MTdlMyZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QifQ.x7vKVrrQmHGm0MXimiZxgXmUhWSs7q4SuXxHa4LcDM0)
Metadata
Assignees
Labels
No labels